conditional-access-mfa
Installation
SKILL.md
Conditional Access & MFA
Conditional Access (CA) is the Zero Trust policy engine in Entra. It evaluates signals - user /group, device state, location, application, sign-in risk - and enforces grant, block, or grant-with-controls (MFA, compliant device, session controls). MFA without CA is rare; the two are designed together.
When to use
Enforcing adaptive, identity-centric access controls across Microsoft 365 and any Entra- integrated app. Use this skill for the baseline policy set and any new policy rollout.
Do not use this skill for risk detection (entra-id-protection), just-in-time admin
elevation (azure-pim), or app-side OAuth permissions (entra-id).
The baseline 6-policy set
Every Entra tenant in 2026 should have these six policies as the minimum, in this order.